CVE-2026-5846 Details
Description
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
A vulnerability exists in Watchfire Controller Software versions BC550 12.30, BC750 11.33 and 12.35, BC760 12.38 and 13.00, and BC760DC 12.39. The issue stems from self-signed, hard-coded RSA private keys and corresponding X.509 certificates embedded in plaintext within the application patch binaries. These keys are used to authenticate and encrypt HTTPS/TLS connections to the controller's web management interface. The hard-coded keys could potentially be exploited to deliver malicious firmware, allowing full control of the affected controller.
Watchfire has issued patches for all affected versions. Users should verify their controller software version and upgrade to an approved version. Specific patch instructions for each version are available in the CISA advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2026CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-09.json | [email protected] | AdvisoryRemedyVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Watchfire BC550 | 12.30 |
CPE
Remediation
| |
| Watchfire BC750 | 11.33 12.35 |
CPE
Remediation
| |
| Watchfire BC760 | 12.38 13.00 |
CPE
Remediation
| |
| Watchfire BC760DC | 12.39 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |
Volerion